Re: Response to phishing email



Fevric J Glandules <fevric@xxxxxxxxxxxxxxx> writes:
Here's a scary screenshot:

http://regmedia.co.uk/2007/05/25/hsbc_spoof.jpg

That's a legit domain name, and a fake site. Not done through
DNS either. (Writing a hosts file entry always seems to me the
best way of going about this, but IANACriminal).

Presumably: pop up a window without the usual browser furniture, fake
it with an image if you're feeling lazy or careful use of HTML if
enthusiastic.

(Browsers allowing web sites to hide this furniture is annoying at the
best of times, and it ought to be considered a security bug.)

Also it's possible to register domains that look very much like the
real thing, but are actually using slightly different characters.

An argument for fonts that deliberately avoid having any pair of
characters look similar. IIRC the Unicode Standard has some
suggestions about flagging names that use characters from different
scripts, but that doesn't help with I/l, l/1, 0/O.

Recently a browser told me that an https site could not be verified
'for unknown reasons'. Hopeless; and of course it still offered me an
OK button to carry on regardless.

--
http://www.greenend.org.uk/rjk/
.



Relevant Pages

  • Re: POSTing Chinese characters
    ... You will have to take a network trace to determine if the missing characters ... clear whether the web browser chose to UTF8-encode the POST data or not. ... and it works in English ...
    (microsoft.public.inetserver.iis)
  • Re: Arabic IIS6 Windows 2003 Issue
    ... encoded correctly between the browser and database. ... I believe that IIS6 is able to correctly handle your scenario, ... English characters tend to work because most character sets keep them at ...
    (microsoft.public.inetserver.iis)
  • Re: String trim (was JavaScript Functions)
    ... Richard's test considers only the characters that he thinks should ... clearly lists all of the character code points. ... Richard's test cannot tell whether a browser is ... accept a newline followed by spaces and HTabs. ...
    (comp.lang.javascript)
  • Re: String trim (was JavaScript Functions)
    ... It also mentions Unicode space separators. ... Those space separators are also clearly defined in Unicode under the White_Space section. ... that NO browser recognises, that's not much of a worry for coders ... representation fails to match some of the characters and also ...
    (comp.lang.javascript)
  • Re: UTF-8 without external modules on Perl 5.0
    ... before general browser support for utf-8 was adequate. ... Users could select an 8-bit web page encoding appropriate to their ... various ways when they attempt to submit characters which cannot be ...
    (comp.lang.perl.misc)